Sploitus

CVE-2013-4885

2 known exploits for CVE-2013-4885

The http-domino-enum-passwords.nse script in NMap before 6.40, when domino-enum-passwords.idpath is set, allows remote servers to upload "arbitrarily named" files via a crafted FullName parameter in a response, as demonstrated using directory traversal sequences.

Affected products
Alt Linux, Nmap
Nmap
≤ 6.25, 2.1, 2.2, 2.3, 2.05, 2.06, 2.07, 2.08, 2.09, 2.10, 2.11, 2.12, 2.50, 2.51, 2.52, 2.53, 2.54, 2.99, 3.00, 3.10, 3.15, 3.20, 3.25, 3.26, 3.27, 3.28, 3.30, 3.40, 3.45, 3.48, 3.50, 3.55, 3.70, 3.75, 3.81, 3.90, 3.91, 3.93, 3.94, 3.95
CVSS 2.0
6.8 MEDIUM
EPSS
7.2% (94th percentile)
NVD status
Modified
Published
2013-10-26
CVE-2013-4885 at NVD
Authoritative description, scoring and affected products

2 known exploits for CVE-2013-4885

Proof-of-concept code and exploit modules indexed by Sploitus